ºÚ¿ÍÔÚÈÈÃźڿÍÂÛ̳ÉÏÉù³Æ¿ÇÅÆÊý¾ÝÔ⵽й¶
Ðû²¼Ê±¼ä 2024-05-315ÔÂ30ÈÕ£¬ÁîÈËÕ𾪵ÄÊÇ£¬Ò»ÃûÍþвÐÐΪÕßÉæÏÓй¶ÁËÌìÏÂÁìÏÈÄÜÔ´¹«Ë¾Ö®Ò»¿ÇÅƵÄÃô¸ÐÊý¾Ý¡£Æ¾Ö¤ Data Web Informer µÄÍÆÎÄ£¬2024 Äê 5 ÔµÄÊý¾Ý±»Ðû²¼ÔÚÒ»¸öÊ¢ÐеĺڿÍÂÛ̳ÉÏ£¬Òý·¢ÁËÈËÃǶÔÍøÂçÇå¾²ºÍÊý¾ÝÒþ˽µÄÑÏÖص£ÐÄ¡£¾Ý±¨µÀ£¬Ð¹Â¶µÄÐÅÏ¢°üÀ¨´ó×ÚСÎÒ˽¼ÒÐÅÏ¢ºÍÃô¸ÐÊý¾Ý¡£Ð¹Â¶µÄÊý¾Ý°üÀ¨£º¹ºÎïÕß´úÂë¡¢Ãû×Ö¡¢ÐÕÊÏ¡¢×´Ì¬¡¢¹ºÎïÕßµç×ÓÓʼþ¡¢ÁªÏµÊÖ»ú¡¢ÓÊÕþ±àÂë¡¢»¨ÃÛ¡¢½¼Çø¡¢ÖÝ¡¢Õ¾µãµØµã¡¢½¼Çø 1¡¢¹ú¼Ò¡¢Õ¾µãÃû³Æ¡¢ÉϴεǼ¡¢¸¶¿îºÍлá±àºÅ¡£´Ë´ÎйÃÜÊÂÎñ¿ÉÄÜ»á¶Ô¿ÇÅƼ°Æä¿Í»§Ôì³ÉÑÏÖØÓ°Ï졣й¶ÔÆÔÆÏêϸµÄСÎÒ˽¼ÒÐÅÏ¢¿ÉÄܻᵼÖÂÉí·Ý͵ÇÔ¡¢½ðÈÚڲƺÍÆäËû¶ñÒâÔ˶¯¡£½¨Òé¿Í»§Ç×½ü¼à¿ØËûÃǵÄÕË»§²¢Á¬Ã¦±¨¸æ¿ÉÒÉÔ˶¯¡£×èÖ¹ÏÖÔÚ£¬¿ÇÅÆÉÐδ¾Í´Ë´ÎйÃÜÊÂÎñ½ÒÏþ¹Ù·½ÉùÃ÷¡£²»¹ý£¬¸Ã¹«Ë¾Ô¤¼Æ½«Æô¶¯ÄÚ²¿ÊӲ죬²¢ÓëÍøÂçÇ徲ר¼ÒÏàÖú£¬ÆÀ¹ÀÎ¥¹æµÄˮƽ²¢¼õÇáÈκÎDZÔÚË𺦡£
https://gbhackers.com/claiming-shell-data-breach/
2. TicketmasterÔâºÚ¿Í¹¥»÷£¬Áè¼Ý5 ÒÚÓû§Êý¾ÝÐÅϢй¶
5ÔÂ30ÈÕ£¬¾Ý±¨µÀ£¬±¾ÖÜÕýÔÚÊÓ²ìµÄÒ»ÆðÍøÂçÊÂÎñÖУ¬Áè¼Ý 5 ÒÚ Ticketmaster Óû§µÄСÎÒ˽¼ÒºÍÐÅÓÿ¨Êý¾ÝÔ⵽й¶¡£¾Ý±¨µÀ£¬°Ä´óÀûÑÇÕþ¸®ÕýÔÚÓë Live Nation ºÍ Ticketmaster ÏàÖú½â¾ö´ËÊÂÎñ£¬µ«×èÖ¹ÖÜÈýÉÏÎ磬Åû¶µÄϸ½ÚÓÐÏÞ¡£¾Ý¸ÃÐÂÎÅýÌ屨µÀ£¬°Ä´óÀûÑÇÄÚÕþ²¿¸æËß ABC£¬ËûÃÇÕýÔÚÓë Ticketmaster ÏàÖúÏàʶ´ËÊ¡£Ticketmaster »òÆäĸ¹«Ë¾ÉÐδ¾Í´ËʽÒÏþÈκÎÉùÃ÷¡£ºÚ¿Í×éÖ¯ ShinyHunters Éù³ÆÒÑÆƽâ Ticketmaster ϵͳ²¢»ñÈ¡ÁËÔ¼ 1.3 TB µÄÊý¾Ý£¬ÆäÖаüÀ¨ÐÕÃû¡¢µØµã¡¢ÐÅÓÿ¨ºÅ¡¢µç»°ºÅÂëºÍ¸¶¿îÏêϸÐÅÏ¢¡£Ìý˵ÕâЩÐÅÏ¢ÔÚ°µÍøÉϳöÊÛ£¬Òª¼Û 50 ÍòÃÀÔª¡£ÔçÆÚ±¨¸æÏÔʾ£¬Óû§Êý¾ÝÉæ¼°È«Çò 5.6 ÒÚ¿Í»§£¬µ«Éв»ÇåÎúÄÄЩÊг¡Êܵ½Ó°Ï죨»òÊÜÓ°ÏìµÄÏûºÄÕßÖÐÓм¸¶àÀ´×ÔÄÄЩÊг¡£©¡£ÏÔÈ»£¬Ë¼Á¿µ½Éæ¼°µÄ¸ß¶ÈÃô¸ÐÊý¾Ý£¬ÈκÎÊÜÓ°ÏìµÄÏûºÄÕßµÄΣº¦¶¼ºÜÊǸߡ£
https://www.ticketnews.com/2024/05/ticketmaster-hack-data-of-half-a-billion-users-up-for-ransom/
3. XWorm v5.6 ¶ñÒâÈí¼þͨ¹ý Webhards ¾ÙÐÐÈö²¥
5ÔÂ30ÈÕ£¬°²ÊµÑéÊÒÇå¾²Ç鱨ÖÐÐÄ£¨ASEC£©ÔÚ¼à¿Øº«¹ú¶ñÒâÈí¼þµÄÈö²¥Ô´Ê±£¬×î½ü·¢Ã÷αװ³É³ÉÈËÓÎÏ·µÄXWorm v5.6¶ñÒâÈí¼þÕýÔÚͨ¹ýÍøÂçÓ²Å̾ÙÐÐÈö²¥¡£ÍøÂçÓ²Å̺ÍÖÖ×ÓÊǺ«¹ú¶ñÒâÈí¼þÈö²¥µÄ³£ÓÃƽ̨¡£¹¥»÷Õßͨ³£Ê¹ÓÃÈÝÒ×»ñµÃµÄ¶ñÒâÈí¼þ£¬ÀýÈç njRAT ºÍ UDP RAT£¬²¢½«Æäαװ³É°üÀ¨ÓÎÏ·»ò³ÉÈËÄÚÈÝÔÚÄÚµÄÕý³£³ÌÐò¾ÙÐзַ¢¡£XWorm v5.6 Ò²¿ÉÒÔ´Ó GitHub µÈƽ̨ÇáËÉ»ñÈ¡¡£ÏÂÔز¢½âѹÓÎÏ·Îļþºó£¬»á»ñµÃ Start.exe¡£ËäÈ»¿´ÆðÀ´ÏñÊÇÕýµ±µÄÓÎÏ·Æô¶¯Æ÷Îļþ£¬µ«Ö´ÐÐÓÎÏ·µÄ .exe ÎļþÊǵ¥¶ÀÌìÉú²¢ÔËÐеģ¬²¢ÇÒαװ³É SoundP2.muc µÄ¼ÓÔسÌÐò¶ñÒâÈí¼þÒ²»á±»Ö´ÐС£Ö´ÐÐ Start.exe ²»»áÁ¬Ã¦ÔËÐжñÒâÈí¼þ»òÓÎÏ·£»ËüÃÇ»áÔÚÄú°´Ï¡°×îÏÈÓÎÏ·£¡¡±°´Å¥Ê±Ö´ÐС£ÕâÖÖÕ½ÂÔËƺõÊÇΪÁËÈƹýɳºÐģʽ¡£SoundP2.muc Ò²±»¸´ÖƲ¢Õ³Ìùµ½ Windows Îļþ¼ÐÖУ¬²¢Ìí¼Óµ½×¢²á±íÖÐÒÔ±ã×Ô¶¯Ö´ÐС£
https://asec.ahnlab.com/en/66099/
4. PyPI¶ñÒâÈí¼þPytoileurÇÔÈ¡¼ÓÃÜÇ®±Ò²¢Èƹý¼ì²â
5ÔÂ31ÈÕ£¬ÍøÂçÇå¾²Ñо¿Ö°Ô±·¢Ã÷ÁË Python Èí¼þ°üË÷Òý£¨PyPI£©ÉϵĶñÒâÈí¼þ°üpytoileur¡£¸ÃÈí¼þ°üαװ³ÉÓà Python ±àдµÄ API ÖÎÀí¹¤¾ß£¬Òþ²ØÁËÏÂÔغÍ×°ÖÃľÂí Windows ¶þ½øÖÆÎļþµÄ´úÂë¡£ÕâЩ¶þ½øÖÆÎļþÄܹ»¾ÙÐмàÊÓ¡¢ÊµÏÖ³¤ÆÚÐÔ²¢ÇÔÈ¡¼ÓÃÜÇ®±Ò¡£¸ÃÈí¼þ°ü±» Sonatype µÄ×Ô¶¯¶ñÒâÈí¼þ¼ì²âϵͳ·¢Ã÷£¬²¢ÔÚ±»±ê¼ÇºóѸËÙ±»É¾³ý¡£pytoileur Èí¼þ°üÔÚ±»ÒƳýÇ°Òѱ»ÏÂÔØ 264 ´Î£¬ËüʹÓÃÁËÓÕÆÐÔÊÖÒÕÀ´×èÖ¹±»¼ì²âµ½¡£ËüµÄÔªÊý¾Ý½«ÆäÐÎòΪ¡°¿áìÅÈí¼þ°ü¡±£¬Ê¹ÓÃÒ»ÖÖÕ½ÂÔ£¬¼´¸øÈí¼þ°üÌùÉÏÎüÒýÈ˵ÄÄ£ºýÐÎò±êÇ©£¬ÒÔÓÕʹ¿ª·¢Ö°Ô±ÏÂÔØËüÃÇ¡£Sonatype ½ñÌìÐû²¼µÄÒ»·Ý×Éѯ±¨¸æÖÐÐÎòÁ˽øÒ»²½µÄ¼ì²é£¬·¢Ã÷Èí¼þ°ü×°ÖÃÎļþÖÐÒþ²Ø×Å´ó×Ú¿Õ¸ñËùÑÚÊεĴúÂë¡£¸Ã´úÂëÖ´ÐÐÁËÒ»¸ö base64 ±àÂëµÄÓÐÓøºÔØ£¬¸Ã¸ºÔØ´ÓÍⲿ·þÎñÆ÷¼ìË÷Á˶ñÒâ¿ÉÖ´ÐÐÎļþ¡£ÏÂÔصĶþ½øÖÆÎļþ¡°Runtime.exe¡±Ê¹Óà PowerShell ºÍ VBScript ÏÂÁî¾ÙÐÐ×ÔÎÒ×°Öã¬È·±£ÔÚÊÜѬȾµÄϵͳÖг¤ÆÚ±£´æ¡£Ëü½ÓÄÉÖÖÖÖ·´¼ì²â²½·¥À´ÌÓ±ÜÇå¾²Ñо¿Ö°Ô±µÄÆÊÎö¡£
https://www.infosecurity-magazine.com/news/pypi-malware-pytoileur-steals/
5. °ÍÎ÷ÒøÐгÉΪ AllaKore RAT бäÖÖ AllaSenha µÄÄ¿µÄ
5ÔÂ29ÈÕ£¬°ÍÎ÷ÒøÐлú×é³ÉΪÐÂÔ˶¯µÄÄ¿µÄ£¬¸ÃÔ˶¯·Ö·¢»ùÓÚ Windows µÄAllaKoreÔ¶³Ì»á¼ûľÂí (RAT)µÄ¶¨ÖƱäÖÖAllaSenha¡£·¨¹úÍøÂçÇå¾²¹«Ë¾ HarfangLabÔÚÒ»·ÝÊÖÒÕÆÊÎöÖÐÌåÏÖ£¬¸Ã¶ñÒâÈí¼þ¡°×¨ÃÅÓÃÓÚÇÔÈ¡»á¼û°ÍÎ÷ÒøÐÐÕË»§ËùÐèµÄƾ֤£¬²¢Ê¹Óà Azure ÔÆ×÷ΪÏÂÁîºÍ¿ØÖÆ (C2) »ù´¡ÉèÊ©¡±¡£´Ë´Î¹¥»÷µÄÄ¿µÄ°üÀ¨°ÍÎ÷ÒøÐС¢Bradesco¡¢Èø·òÀÒøÐС¢Caixa Econ?mica Federal¡¢Ita¨² Unibanco¡¢Sicoob ºÍ Sicredi µÈÒøÐС£ËäÈ»ÉÐδ»ñµÃÃ÷ȷ֤ʵ£¬µ«×î³õµÄ»á¼ûÔØÌåÖ¸ÏòÁË´¹ÂÚÓʼþÖÐʹÓöñÒâÁ´½Ó¡£¹¥»÷µÄÆðµãÊÇÒ»¸ö¶ñÒâµÄ Windows ¿ì½Ý·½·¨ (LNK) Îļþ£¬¸ÃÎļþαװ³É PDF Îĵµ£¨¡°NotaFiscal.pdf.lnk¡±£©£¬ÖÁÉÙ×Ô 2024 Äê 3 ÔÂÆðÍйÜÔÚ WebDAV ·þÎñÆ÷ÉÏ¡£ÉÐÓÐÖ¤¾ÝÅú×¢£¬¸ÃÔ˶¯±³ºóµÄÍþвÐÐΪÕß֮ǰÔøÀÄÓà Autodesk A360 Drive ºÍ GitHub µÈÕýµ±·þÎñÀ´ÍйÜÓÐÓøºÔØ¡£
https://thehackernews.com/2024/05/brazilian-banks-targeted-by-new.html
6. ʹÓÃDora RATÕë¶Ôº«¹úÆóÒµ£¨Andariel Group£©µÄAPT¹¥»÷
5ÔÂ30ÈÕ£¬AhnLab Çå¾²Ç鱨ÖÐÐÄ (ASEC) ×î½ü·¢Ã÷ÁËÕë¶Ôº«¹ú¹«Ë¾ºÍ»ú¹¹µÄ Andariel APT ¹¥»÷°¸Àý¡£Ä¿µÄ×éÖ¯°üÀ¨º«¹úµÄ½ÌÓý»ú¹¹ÒÔ¼°ÖÆÔìºÍÐÞ½¨ÆóÒµ¡£¹¥»÷ʹÓÃÁ˺óÃÅÉϵļüÅ̼ͼÆ÷¡¢ÐÅÏ¢ÇÔÈ¡³ÌÐòºÍÊðÀí¹¤¾ß¡£ÍþвÐÐΪÕß¿ÉÄÜʹÓÃÕâЩ¶ñÒâÈí¼þÀ´¿ØÖƺÍÇÔÈ¡ÊÜѬȾϵͳµÄÊý¾Ý¡£´Ë´Î¹¥»÷ʹÓÃÁË Andariel ¼¯ÍÅÒÑÍù°¸ÀýÖз¢Ã÷µÄ¶ñÒâÈí¼þ£¬ÆäÖÐ×îÒýÈËעĿµÄÊÇ Nestdoor£¬ÕâÊDZ¾ÎÄÖÐÌáµ½µÄºóÃÅ¡£ÆäËû°¸Àý°üÀ¨Ìí¼Ó Web Shell¡£Lazarus ¼¯ÍÅÏÈÇ°¹¥»÷Öз¢Ã÷µÄÊðÀí¹¤¾ßÒ²±»Ê¹Óã¬Ö»¹ÜËüÃǵÄÎļþÓëÄ¿½ñ°¸Àý²¢²»Ïàͬ¡£ÔÚ¹¥»÷Àú³ÌÖеÄÖÚ¶àÖ¤¾ÝÖУ¬Ò»¸öÏÖʵ±»Ö¤ÊµµÄ°¸ÀýÉ漰ʹÓÃÔËÐÐ Apache Tomcat ·þÎñÆ÷µÄ Web ·þÎñÆ÷·Ö·¢¶ñÒâÈí¼þ¡£ÓÉÓÚÓÐÎÊÌâµÄϵͳÔËÐеÄÊÇ 2013 °æ Apache Tomcat£¬Òò´ËÈÝÒ×Êܵ½ÖÖÖÖÎó²î¹¥»÷¡£ÍþвÐÐΪÕßʹÓøà Web ·þÎñÆ÷×°ÖúóÃÅ¡¢ÊðÀí¹¤¾ßµÈ¡£
https://asec.ahnlab.com/en/66088/